Two regimes, two different starting assumptions, and one practical consequence: consent is the wrong basis for most employment processing under one of them and central to the other.

A general orientation, not a legal summary. Both regimes are more detailed than any table can convey and both are subject to guidance and change. Take advice for each jurisdiction.
An organisation employing people in Europe and in India is subject to two data protection regimes that were built on different assumptions and arrive, on most operational questions, at similar destinations by different routes.
This is a plain-language orientation for HR practitioners. It is not legal advice, it is not a substitute for reading the instruments, and both are more detailed than any article can convey.
The starting assumptions differ, and it matters
The General Data Protection Regulation, Regulation (EU) 2016/679, sets out several lawful bases for processing personal data. Consent is one of them. In the employment context it is generally treated as a weak basis, because the imbalance of power between employer and employee makes it difficult to argue that consent was freely given and could be withdrawn without consequence.
Most employment processing under the GDPR therefore rests on performance of the employment contract, compliance with a legal obligation, or legitimate interests subject to a balancing assessment.
India's Digital Personal Data Protection Act 2023 is consent-forward by design, with notice and consent central to the framework. It also sets out defined legitimate uses for which consent is not required, and employment purposes are among them.
The practical trap runs in both directions. A global policy that requires employee consent for everything will produce weak compliance in Europe. One that assumes consent is never relevant will not fit India. The same processing needs different documentation in each.
What employees can ask for
Under the GDPR, individuals in the EEA can request a copy of their personal data, have inaccurate data corrected, request erasure, restrict processing, object to processing based on legitimate interests, and receive certain data in a portable format. Where consent is the basis, it can be withdrawn.
Under the DPDP Act, individuals can obtain a summary of the personal data being processed and the processing activities, seek correction, completion, updating and erasure, nominate another individual to exercise their rights in the event of death or incapacity, and access a grievance redressal mechanism. Consent may be withdrawn.
The nomination right has no direct GDPR equivalent and is worth noting operationally, because it requires a mechanism rather than merely a policy.
For an HR team the sensible design is a single request-handling process built to the wider set of rights, with jurisdiction-specific timescales and exceptions applied within it. Running two processes produces inconsistency and neither will be well practised, because the volume in most organisations is low enough that the process is only exercised occasionally.
The two questions that cause the most difficulty
Retention. Both regimes limit retention to what is necessary for the purpose. Employment creates genuine long-tail obligations, including tax, pension, occupational health and limitation periods for claims, which differ by jurisdiction and can be lengthy.
The practical answer is a documented retention schedule by record type, by jurisdiction, with the legal basis for each period recorded. Most organisations have a policy expressing a general principle and no schedule, which means retention decisions are made informally by whoever happens to be clearing a system.
Transfers. Employee data moves constantly: to a global HR system, to payroll providers, to benefits administrators, to a parent company. Under the GDPR, transfers outside the EEA require a recognised safeguard. Under the DPDP Act, the government may restrict transfers to notified countries.
Both require you to know where the data goes. Most organisations discover during a mapping exercise that employee data reaches more places than anyone had listed, usually via reports and exports rather than via documented integrations.
The categories that carry extra weight
Health data, and in most regimes several other categories, attract additional conditions. In HR they appear routinely: occupational health records, absence reasons, adjustments, benefits enrolment involving dependants, and sometimes diversity monitoring data.
The common failure is not deliberate misuse. It is special category data arriving in a general-purpose system, such as an absence reason typed into a free-text field, and inheriting that system's access model, which is far broader than the data warrants.
Where this intersects with AI
Where a decision about an individual is made solely by automated means with legal or similarly significant effects, the GDPR imposes specific requirements. Separately, Annex III of Regulation (EU) 2024/1689, the AI Act, classifies AI systems used in employment and worker management as high risk. Those obligations were to apply from 2 August 2026. Regulation (EU) 2026/1744, the Digital Omnibus on AI, adopted on 8 July 2026, defers them to 2 December 2027 and enters into force on 27 July 2026.
These are separate regimes with overlapping subject matter. Compliance with one does not discharge the other.
A practical checklist
Record the lawful basis for each category of employment processing, per jurisdiction, not per system.
Produce a retention schedule by record type with the legal reason for each period. A principle is not a schedule.
Map where employee data actually goes, including exports and reports, not only documented integrations.
Build one rights-request process to the wider set of rights, with jurisdiction-specific rules inside it, and rehearse it.
Find the special category data sitting in free-text fields and decide what to do about it.
Establish a nomination mechanism for DPDP purposes rather than a policy statement.
Keep a record of automated decision-making about individuals, because you will be asked for it under more than one regime.
What this article is not. It is an orientation for practitioners, not a legal summary. We have not set out thresholds, exemptions, timescales or penalties, all of which are jurisdiction-specific and subject to guidance and amendment. Take qualified advice for each place you employ people.
This is reporting, not legal advice. Employment and data protection obligations differ significantly by jurisdiction and change frequently. Take qualified legal advice on your specific circumstances.
References
Every figure and legal citation in this article is drawn from the sources below. Where an instrument is proposed rather than in force we say so in the text.
European Union, Regulation (EU) 2016/679, the General Data Protection Regulation. https://eur-lex.europa.eu/eli/reg/2016/679/oj
Government of India, The Digital Personal Data Protection Act, 2023, data protection framework. https://www.meity.gov.in/data-protection-framework
European Union, Regulation (EU) 2024/1689, the AI Act, Annex III on employment and worker management. https://artificialintelligenceact.eu/annex/3/
European Union, Regulation (EU) 2026/1744, the Digital Omnibus on AI, deferring Annex III obligations to 2 December 2027, in force 27 July 2026. https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng
Information Commissioner's Office, Guide to PECR, under review following the Data (Use and Access) Act 2025, page dated 20 August 2025. https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/guide-to-pecr/
How we work. This article was researched and written by the HR Hubs Media editorial team. We do not republish press releases. Every number and legal citation is checked against a primary source, which is named and linked above. Where an instrument is proposed rather than in force, we say so. Corrections are made openly on the article itself, never by silent edit. If you believe something here is wrong, write to info@hrhubsmedia.com and tell us what and why.
Filed under Employee Data & Privacy · Get The Weekly Brief

